This document describes the features, configurations and APIs in Cloud Build that align
with the controls for supported control packages. This document assumes that
you're using Assured Workloads .
Show All
Data Boundary for ITAR
Data Boundary for ITAR
Supported services
The following table lists the Cloud Build APIs and versions that meet the requirements of Data Boundary for ITAR.
Service
Version
Status
cloudbuild.googleapis.com
v1
SUPPORTED
cloudbuild.googleapis.com
v2
SUPPORTED
Compliance supported regions
Cloud Build is available for Data Boundary for ITAR in the following Google Cloud regions:
us-central1
us-central2
us-east1
us-east4
us-east5
us-south1
us-west1
us-west2
us-west3
us-west4
API fields for sensitive data
Resource: No resource
The following table specifies the API resources and fields that are designed to handle data that is protected under Data Boundary for ITAR.
API Method
Protected fields
Service: cloudbuild.googleapis.com
REST API: POST /v1/appmanifest:constructAppManifest
RPC methods:
google.devtools.cloudbuild.v1.CloudBuild.ConstructAppManifest
Service: cloudbuild.googleapis.com
REST API: POST /v1/{parent=projects/*/locations/*}/appmanifest:constructAppManifest
RPC methods:
google.devtools.cloudbuild.v1.CloudBuild.ConstructAppManifest
Resource: cloudbuild.googleapis.com/Build
The following table specifies the API resources and fields that are designed to handle data that is protected under Data Boundary for ITAR.
API Method
Protected fields
Service: cloudbuild.googleapis.com
REST API: GET /v1/projects/{project_id}/builds
RPC methods:
google.devtools.cloudbuild.v1.CloudBuild.ListBuilds
Service: cloudbuild.googleapis.com
REST API: GET /v1/{parent=projects/*/locations/*}/builds
RPC methods:
google.devtools.cloudbuild.v1.CloudBuild.ListBuilds
Service: cloudbuild.googleapis.com
REST API: POST /v1/projects/{project_id}/builds
RPC methods:
google.devtools.cloudbuild.v1.CloudBuild.CreateBuild
build.artifacts.genericArtifacts.contentHandling
build.artifacts.genericArtifacts.folder
build.artifacts.genericArtifacts.registryPath
build.artifacts.goModules.modulePath
build.artifacts.goModules.moduleVersion
build.artifacts.goModules.sourcePath
build.artifacts.images
build.artifacts.mavenArtifacts.artifactId
build.artifacts.mavenArtifacts.deployFolder
build.artifacts.mavenArtifacts.groupId
build.artifacts.mavenArtifacts.path
build.artifacts.mavenArtifacts.pomPath
build.artifacts.mavenArtifacts.version
build.artifacts.npmPackages.archive
build.artifacts.npmPackages.packagePath
build.artifacts.npmPackages.repository
build.artifacts.objects.location
build.artifacts.objects.paths
build.artifacts.oci.file
build.artifacts.oci.registryPath
build.artifacts.oci.tags
build.artifacts.pythonPackages.paths
build.artifacts.testResults.bucketUri
build.artifacts.testResults.format
build.artifacts.testResults.paths
build.artifacts.volumes.name
build.artifacts.volumes.path
build.availableSecrets.inline.envMap.key
build.availableSecrets.inline.envMap.value
build.availableSecrets.inline.kmsKeyName
build.availableSecrets.secretManager.env
build.availableSecrets.secretManager.versionName
build.buildReceipt.workerDiagnostics.identityEndpointSuccesses
build.dependencies.empty
build.dependencies.genericArtifact.destPath
build.dependencies.genericArtifact.resource
build.dependencies.gitSource.depth
build.dependencies.gitSource.destPath
build.dependencies.gitSource.recurseSubmodules
build.dependencies.gitSource.repository.developerConnect
build.dependencies.gitSource.repository.proxyUrlEnabled
build.dependencies.gitSource.repository.url
build.dependencies.gitSource.revision
build.gitConfig.http.proxySecretVersionName
build.gitConfig.http.sslCaInfo
build.images
build.logsBucket
build.options.env
build.options.secretEnv
build.options.volumes.name
build.options.volumes.path
build.secrets.kmsKeyName
build.secrets.secretEnv.key
build.secrets.secretEnv.value
build.serviceAccount
build.source.buildConfigFileName
build.source.connectedRepository.dir
build.source.connectedRepository.repository
build.source.connectedRepository.revision
build.source.developerConnectConfig.dir
build.source.developerConnectConfig.gitRepositoryLink
build.source.developerConnectConfig.revision
build.source.gitSource.commitSha
build.source.gitSource.dir
build.source.gitSource.revision
build.source.gitSource.url
build.source.repoSource.branchName
build.source.repoSource.commitSha
build.source.repoSource.dir
build.source.repoSource.invertRegex
build.source.repoSource.projectId
build.source.repoSource.repoName
build.source.repoSource.substitutions.key
build.source.repoSource.substitutions.value
build.source.repoSource.tagName
build.source.storageSource.bucket
build.source.storageSource.generation
build.source.storageSource.object
build.source.storageSource.sourceFetcher
build.source.storageSource.stripComponents
build.source.storageSourceManifest.bucket
build.source.storageSourceManifest.generation
build.source.storageSourceManifest.object
build.steps.args
build.steps.dir
build.steps.entrypoint
build.steps.env
build.steps.id
build.steps.name
build.steps.remoteConfig
build.steps.results.attestationContent
build.steps.results.attestationType
build.steps.results.name
build.steps.script
build.steps.secretEnv
build.steps.volumes.name
build.steps.volumes.path
build.steps.waitFor
build.substitutions.key
build.substitutions.value
build.tags
Service: cloudbuild.googleapis.com
REST API: POST /v1/{name=projects/*/builds/*}:approve
RPC methods:
google.devtools.cloudbuild.v1.CloudBuild.ApproveBuild
approvalResult.comment
approvalResult.url
Service: cloudbuild.googleapis.com
REST API: POST /v1/{name=projects/*/locations/*/builds/*}:approve
RPC methods:
google.devtools.cloudbuild.v1.CloudBuild.ApproveBuild
approvalResult.comment
approvalResult.url
Service: cloudbuild.googleapis.com
REST API: POST /v1/{parent=projects/*/locations/*}/builds
RPC methods: